Frédéric<bold>, </bold>I'm very uncomfortable moving toward ACKs in ESP. We try in IPsec to mimic IP functionality as much as possible, and IP does not ACK packets. Note that our anti-replay strategy allows for out of order arrival precisely because IP allows for it (even though we do impose <underline>some</underline> limits here). Steve